Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-46701

Description

The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.

POC

Reference

- http://seclists.org/fulldisclosure/2022/Dec/20

- http://seclists.org/fulldisclosure/2022/Dec/23

- http://seclists.org/fulldisclosure/2022/Dec/26

Github

- https://github.com/felix-pb/remote_pocs